Staples, Inc.
bd_3b23b3c8515a9da1 · schema v1 · pii pii-v1
Full breach record for Staples, Inc. →5 incidents on fileStaples, Inc. notified the NH AG of malware detected on POS systems in mid-Sept 2014. Unauthorized access to payment card data (names, numbers, CVVs) occurred between July 20 and Sept 16, 2014. No NH stores affected. Total affected count unknown. Staples eradicated malware, engaged experts, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 20, 2014
Begins
Sep 1, 2014
Discovered
Dec 19, 2014
Filed
vs. sector median
+8 wks slower
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- California State AGbd_86c2f1aade9673822014-12-19Candidate
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.